Responsible for executing the IT compliance review plan, monitoring key risk indicators (KRIs), and ensuring that our controls particularly those governing our Policy Administration System (PAS) and participant data are operating effectively. You will act as the bridge between our technical IT teams and the auditors, ensuring evidence is clear, gaps are tracked, and the company remains perpetually audit-ready.
Compliance Monitoring & Assurance
- Control Testing: Execute scheduled compliance reviews and control tests (e.g., quarterly user access reviews, change management logs, backup verification) to assess the operating effectiveness of IT General Controls (ITGCs).
- Shariah Compliance Support: Conduct specific monitoring activities to ensure IT systems maintain the required segregation between Participant's Risk Fund (PRF) and Shareholders Fund data, providing evidence for Shariah audits.
- Regulatory Mapping: Map existing IT controls to specific regulatory requirements (e.g., RMiT, Technology Risk Management) to identify gaps and areas for improvement.
- Data Privacy Monitoring: Assist in monitoring compliance with data protection laws (e.g., PDPA, GDPR), ensuring that participant data handling practices adhere to policy.
Audit Coordination & Evidence Management
- Evidence Collection: Serve as the primary collector of evidence for internal audits, external audits, and regulatory inspections. Liaise with IT operations teams to obtain system logs, configuration screenshots, and access reports.
- Finding Tracking: Manage the lifecycle of audit findings and remediation actions in a centralized tracking system (e.g., Jira, ServiceNow, or Excel), ensuring owners are aware of deadlines.
- Documentation: Maintain a well-organized repository of compliance artifacts, policies, and evidence to ensure perpetual audit readiness.
Awareness & Reporting
- Compliance Reporting: Prepare clear and concise compliance dashboards and reports for the IT GRC Manager and the IT Steering Committee.
- Policy Communication: Assist in communicating new IT policies or control requirements to staff, explaining the what and the why to foster a culture of compliance.
Education & Experience
- Bachelor's degree in information technology, Computer Science, or a related field.
- 2–4 years of experience in an IT compliance, IT audit, or IT risk management role.
- Essential: Experience working within the Financial Services industry (Banking, Insurance, or Takaful) is highly preferred.